Security Advisory for Unquoted service path vulnerability in Tosibox Key software


Description

IDTBSA-024-101
DATE ISSUED2024-02-23
ISSUEUnquoted service path vulnerability in Tosibox Key software for Windows.
STATUSFixed
RISK LEVELHigh
FIXThe new version (3.3.1) of Tosibox Key for Windows has been released and is available as software update.
ACTION REQUIREDCustomers are advised to upgrade to the latest version at their earliest convenience.

 

Affected products and versions

 

More information

Tosibox was informed about the issue in Tosibox Key software that could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.

 

Acknowledgement

Tosibox would like to thank Gjoko Krstic from Zero Science Lab for reporting this vulnerability under responsible disclosure.